LiveActive security incident?Get immediate response
CVE Record

CVE-2020-25890: The web application of Kyocera printer (ECOSYS M2640IDW) is affected by Stored XSS vulnerability, discovere...

The web application of Kyocera printer (ECOSYS M2640IDW) is affected by Stored XSS vulnerability, discovered in the addition a new contact in "Machine Address Book". Successful exploitation of this vulnerability can lead to session hijacking of the administrator in the web application or the execution of unwanted actions

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

CVE-2020-25890 is a stored cross-site scripting issue in the web application of Kyocera ECOSYS M2640IDW printers. A malicious address book contact could later run script in an administrator’s browser, potentially hijacking the admin session or causing unwanted actions.

Executive priority

Treat as a moderate priority for environments using this printer model, especially if management interfaces are broadly reachable. The main business risk is compromise of printer administration through an administrator’s browser session.

Technical view

The reported flaw is stored XSS during creation of a new contact in the Machine Address Book. The CVE record provides no CVSS score, CWE, affected firmware range, or official fix details. The available impact statement is administrator session hijacking or unintended web-application actions.

Likely exposure

Exposure is most likely where Kyocera ECOSYS M2640IDW printer web administration is reachable and users can add or modify Machine Address Book contacts. Internet-exposed admin panels would raise risk, but the sources do not confirm affected firmware versions.

Exploitation context

The source bundle does not show CISA KEV listing or confirmed active exploitation. Exploitation appears to require storing malicious content in the address book and an administrator later viewing affected web application content.

Researcher notes

Evidence is limited to the CVE description and a public researcher reference. The CVE metadata lacks version ranges, CVSS, CWE, and remediation details, so validation should focus on asset identification, interface exposure, and vendor-confirmed firmware status.

Mitigation direction

  • Restrict printer web administration to trusted management networks or VPN only.
  • Remove internet exposure for printer administrative interfaces.
  • Limit address book modification privileges to trusted administrators.
  • Check Kyocera support channels for firmware updates or official mitigation guidance.
  • Review and remove suspicious address book entries after preserving evidence.

Validation and detection

  • Inventory Kyocera ECOSYS M2640IDW printers and record firmware versions.
  • Confirm whether the web admin interface is reachable from untrusted networks.
  • Review address book entries for unexpected script-like content.
  • Check logs for unusual address book changes or administrator actions.
  • Track vendor guidance because the provided sources do not name a patch.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2020-25890 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.